Vulnerability record · CVE-2020-13927 · published 10 November 2020
CVE-2020-13927: Apache Airflow Experimental API missing authentication by default
Apache · Airflow
Airflow's Experimental API defaulted to allowing all requests without authentication, so any reachable instance exposed its API to unauthenticated callers. Airflow 1.10.11 changed the default to deny all requests, but existing installations must explicitly set the deny_all auth backend to be protected. The flaw matters because it is a missing-authentication issue on a critical function in a widely deployed orchestration platform.
Description
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been changed to deny all requests by default and is documented at https://airflow.apache.org/docs/1.10.11/security.html#api-authentication. Note this change fixes it for new installs but existing users need to change their config to default `[api]auth_backend = airflow.api.auth.backend.deny_all` as mentioned in the Updating Guide: https://github.com/apache/airflow/blob/1.10.11/UPDATING.md#experimental-api-will-deny-all-request-by-default
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, KEV-listed, near-maximum EPSS, and public exploit code make this an urgent unauthenticated remote compromise risk.
What it is
Airflow's Experimental API defaulted to allowing all requests without authentication, so any reachable instance exposed its API to unauthenticated callers. Airflow 1.10.11 changed the default to deny all requests, but existing installations must explicitly set the deny_all auth backend to be protected. The flaw matters because it is a missing-authentication issue on a critical function in a widely deployed orchestration platform.
Impact
An unauthenticated attacker gains full access to the Experimental API, which can lead to remote code execution and complete compromise of the Airflow instance and its managed workflows.
Attack surface
Reachable over the network via the Airflow Experimental API endpoint; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Listed in CISA KEV since 2022-01-18 with a required action to apply vendor updates, and EPSS shows a 30-day probability of 0.99778 (percentile 0.99955); public exploit references exist on Packet Storm.
What to do
- Upgrade to Airflow 1.10.11 or later, which denies Experimental API requests by default.
- On existing installs, set [api]auth_backend = airflow.api.auth.backend.deny_all in airflow.cfg per the Updating Guide.
- If the Experimental API is not needed, disable it entirely.
- Restrict network access to the Airflow web/API port to trusted hosts only.
- Review Airflow configuration for any other unauthenticated endpoints or insecure defaults.
Detection
- Monitor Airflow API access logs for requests to Experimental API endpoints from unexpected or unauthenticated sources.
- Alert on configuration changes to [api]auth_backend or other Airflow security settings.
- Hunt for signs of unauthorized DAG creation or modification, which may indicate API abuse.
- Check for outbound connections or process execution on Airflow hosts consistent with post-exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-13927 to the Known Exploited Vulnerabilities catalog on 18 January 2022 as "Apache Airflow's Experimental API Authentication Bypass". Required action: Apply updates per vendor instructions. Federal deadline 18 July 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/162908/Apache-Airflow-1.10.10-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/174764/Apache-Airflow-1.10.10-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://lists.apache.org/thread.html/r23a81b247aa346ff193670be565b2b8ea4b17ddbc7a35fc099c1aadd%40%3Cdev.airflow.apache.o | Mailing ListVendor Advisory |
| http://packetstormsecurity.com/files/162908/Apache-Airflow-1.10.10-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/174764/Apache-Airflow-1.10.10-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://lists.apache.org/thread.html/r23a81b247aa346ff193670be565b2b8ea4b17ddbc7a35fc099c1aadd%40%3Cdev.airflow.apache.o | Mailing ListVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-13927 | Third Party AdvisoryUS Government Resource |
Track CVE-2020-13927 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-13927), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.